The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade file | Aug 30, 2017 | Jan 21, 2015 |
| Debian | — | Upgrade file | Jul 30, 2024 | Jan 21, 2015 |
| Gentoo Linux | — | Upgrade sys-apps/file. | Oct 30, 2017 | Jan 21, 2015 |
| Suse | — | Upgrade libmagic1Upgrade python-magicUpgrade file-magicUpgrade file-develUpgrade fileUpgrade libmagic1-32bit | Nov 22, 2017 | Jan 21, 2015 |
| Ubuntu | — | Upgrade libmagic1Upgrade file | Jun 27, 2018 | Jan 21, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub